Known CVE
MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass
MLflow > 3.15.0 contains an information disclosure vulnerability caused by improper validation of webhook URLs allowing attackers to reach internal or cloud metadata services and obtain response details, exploit requires unauthenticated access to the webhook test endpoint.
CVE-2026-64849
Critical2026CVSS 9.3CWE-918
cve2026 · mlflow · ssrf · oast · webhook · oss · vkev · kev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website